T03 · Remote Payload Retrieval and Execution
- Location
references/apm.md:383- Finding
Java monitoring agent downloaded over plaintext HTTP and executed without integrity verification
- Content
View full analysis
Vulnerability Details
File Location:
references/apm.md:383-384
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash wget -T 30 -t 3 "http://arms-apm-{regionId}.oss-{regionId}[-internal].aliyuncs.com/AliyunJavaAgent.zip" -O AliyunJavaAgent.zip unzip AliyunJavaAgent.zip -d /opt/Technical Analysis
The workflow downloads an executable Java monitoring agent over plaintext HTTP and extracts it into
/opt/without verifying a cryptographic signature, checksum, pinned version, or trusted final download destination.Because HTTP does not provide transport integrity or server authentication, a network-positioned attacker could replace the ZIP archive in transit. A compromised object-storage account, DNS path, proxy, or delivery endpoint could produce the same result. The extracted JAR is subsequently loaded using Java's
-javaagentmechanism, so its initialization code executes inside the monitored JVM.No archive-content validation is required before extraction. A malicious archive could therefore also contain unexpected files or path traversal entries, depending on the behavior and version of the local extraction utility.
Attack Path
- A user follows the documented Java onboarding workflow.
- The host downloads
AliyunJavaAgent.zipthrough an unencrypted HTTP connection. - An attacker with control over the network path, DNS resolution, proxy, storage object, or delivery endpoint substitutes a modified archive.
- The untrusted archive is extracted into
/opt/without checksum or signature verification. - The application is restarted with the downloaded JAR specified through
-javaagent. - The substituted code executes with the same operating-system identity and effective privileges as the Java application.
Impact Assessment
Successful exploitation provides arbitrary code execution within the instrumented Java process. The payload could access appli ...[truncated 451 chars]
- Remediation
View remediation
Remediation Suggestions
- Require HTTPS for every public and VPC download endpoint.
- Pin an explicit, reviewed agent version rather than retrieving a mutable default artifact.
- Publish an expected SHA-256 or stronger digest through an independently authenticated channel and verify it before extraction.
- Prefer vendor-signed artifacts and validate the signature against a pinned vendor public key.
- Disable or strictly validate redirects, and allow only approved Alibaba Cloud hostnames.
- Inspect ZIP entries before extraction and reject absolute paths, symbolic links, and
../traversal entries. - Download to a restricted temporary directory, validate the artifact, and only then install it into
/opt/. - Run the application and agent under a dedicated, least-privileged operating-system account.
- Abort installation when any transport, checksum, signature, hostname, or archive validation fails.
